Texas Responsible Artificial Intelligence Governance Act (HB 149)
Last reviewed Sep 25, 2026.
In short
TRAIGA took effect on 1 January 2026. Instead of a broad high-risk regime, it bans AI built or used with intent to manipulate people into self-harm or crime, to discriminate unlawfully, to run government social scoring or biometric identification, or to make sexual deepfakes and CSAM. Government agencies must tell people when they interact with AI; healthcare providers must disclose AI used in treatment. The Attorney General enforces it after a 60-day cure period, there is no private right of action, and following NIST's AI RMF is a defence.
Who it applies to
- Organisations that build or use AI systems in United States · Texas.
- Any use case — it is not limited to specific applications.
- Size: everyone, including solo operators.
- Applies to anyone doing business in Texas or serving Texas residents. Most duties are intent-based bans; specific disclosure duties apply to government agencies and healthcare providers.
Key dates
- Jun 22, 2025✓Signed by Governor Abbott
- Jan 1, 2026✓In effect
What you have to do
- Document the purpose of each AI system so you can show it was not built or deployed with a prohibited intent.
- If you are a state agency (or supply one), disclose clearly, before or at the point of interaction, that a person is dealing with AI.
- If you are a healthcare provider, tell patients when AI is used in their treatment, no later than when the service is first provided.
- Do not use AI to identify people from biometric data or to score citizens' behaviour on behalf of government.
- Adopt a recognised framework such as NIST AI RMF: it is an affirmative defence.
- Set up a process to respond to an AG notice within the 60-day cure window.
Penalties
Civil penalties of $10,000–$12,000 per curable violation, $80,000–$200,000 per uncurable violation, and $2,000–$40,000 per day for continuing violations, enforced only by the Texas Attorney General after a 60-day notice-and-cure period. No private lawsuits.
Related lessons
- Level 1What AI compliance is (and who the rules target)6 min
- Level 1The world map of AI rules: EU, US patchwork, Canada, standards8 min
- Level 2Risk classification: prohibited, high-risk, limited, minimal8 min
- Level 2Data and privacy basics for AI7 min
- Level 2Transparency and disclosure: telling people AI is involved7 min
- Level 3Bias and fairness testing, including bias audits8 min
- Level 4Governance structure and roles6 min
- Level 4Training and AI literacy programmes6 min
- Level 5Management systems in practice: ISO 42001, NIST AI RMF and continuous assurance8 min
- Level 5Preparing for enforcement, investigations and appeals7 min
Real cases
- Ban2023 · US-federalFTC v. Rite Aid — five-year ban on facial recognition surveillance
Settlement announced 19 December 2023. Rite Aid is banned from using facial recognition for surveillance for five years, must delete the images and any models built from them, must notify consumers before enrolling them in any future biometric system, run a comprehensive security programme with independent assessments for 20 years, and have its CEO certify compliance annually.
- Fine2024 · EUClearview AI — EUR 90 million-plus in GDPR fines across Europe
Fines totalling more than EUR 95 million across four countries (plus a UK ICO fine on separate grounds). Clearview has no EU establishment and is reported as having neither paid nor changed its practices, which is why the Dutch DPA is pursuing directors and warning customers that using the service is itself unlawful.
Industries where it matters
Sources
- HB 149 enrolled text — Texas Legislature Online ↗
- The Texas Responsible AI Governance Act — Norton Rose Fulbright ↗
- Texas Enacts Responsible AI Governance Act — Baker Botts ↗
Last reviewed Sep 25, 2026.